Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wh8v-ph87-c4fh

Опубликовано: 16 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 8.4

Описание

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.

EPSS

Процентиль: 26%
0.00334
Низкий

9.3 Critical

CVSS4

8.4 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.4
nvd
7 месяцев назад

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.

CVSS3: 7.1
fstec
7 месяцев назад

Уязвимость программного обеспечения для онлайн-моделирования и оптимизации процессов AVEVA Process Optimization, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю выполнить произвольный код, повысить свои привилегии и получить полный контроль над системой

EPSS

Процентиль: 26%
0.00334
Низкий

9.3 Critical

CVSS4

8.4 High

CVSS3

Дефекты

CWE-89